---
id: CVE-2026-37236
title: grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control
summary: >-
  grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The
  application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP
  without restricting allowed methods. When a POST request with Content-Type
  application/x-ww…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-639
  - CWE-444
published: '2026-08-28'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:42:20.313'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-37236'
references:
  - url: 'https://github.com/grpc-ecosystem/grpc-gateway'
    label: cve@mitre.org
  - url: >-
      https://github.com/grpc-ecosystem/grpc-gateway/commit/72123cd4f32545f6e1376873f412dcdcbcf29acc
    label: cve@mitre.org
  - url: 'https://s00me00ne.com/cve/cve-2026-37236/'
    label: cve@mitre.org
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-37236.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-37236'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2525631'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-37236'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-37236'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - score-dispute
epss: 0.00638
epssPercentile: 0.48284
ingestedAt: '2026-09-08T20:10:03.159Z'
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - cryostat 4
  - migration_toolkit_for_applications 8
  - multicluster_global_hub
  - openshift_serverless
  - advanced_cluster_management_for_kubernetes 2
  - ceph_storage 5
  - ceph_storage 6
  - ceph_storage 7
  - ceph_storage 8
  - ceph_storage 9
  - enterprise_linux 8
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openshift_gitops
  - openshift_virtualization 4
scores:
  nvd: 9.8
  vendor: 5.4
---

## Overview

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Cryostat 4, Migration Toolkit for Applications 8, Multicluster Global Hub, OpenShift Serverless, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 5, … · no fix planned: Red Hat OpenShift Container Platform 4, Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, Red Hat Ceph Storage 7, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-37236.json)
